Only the data the task needs.
CASEY works with pay stubs, ID cards, leases and benefit letters, for people who cannot afford a mistake. Here is what it asks for, who sees it, and how long it is kept.
SOC 2 Type 2
Independently audited controls. Additional frameworks are scoped to what your programs require, as part of pilot design.
Four rules.
-
01
Asked only when a task needs it.
CASEY asks for a detail at the step that needs it, and not before. Every task runs with only the context and permissions it requires.
-
02
Sent only after the person says yes.
Before anything goes to a pharmacy, a fund or any other provider, CASEY says what will be sent and to whom, and waits for the answer.
-
03
Kept only while it is needed.
A document uploaded for one task is deleted when that task closes. Anything kept for a later step is named in the conversation.
-
04
Never used to train a model.
What a person says or sends to CASEY stays out of training, at Humanitas and at every model vendor. Each vendor is bound to that by contract.
One electric bill, start to finish.
CASEY
Text message · no app required
- Heads up, the electric company letter you uploaded last week says the power goes off on the 15th unless the bill is paid. A local hardship fund can cover it. Want me to apply?
- yes what do they need
- Proof of income and the letter, which I already have. Your latest pay stub covers the income. Upload a photo of it here: Upload your pay stub textcasey.com/u/4k7m2x
- Got it. Your income is under their limit. Okay to send the stub and the letter to the fund?
- yes
- Sent. They usually answer within a day and pay the electric company directly. I'll tell you as soon as they do.
- Approved this morning. The fund paid the bill in full. The power stays on.
System activity
- Letter $312 owed, power off on the 15th read
- Pay stub IMG_4127.jpg, secure page received
- Stored Humanitas systems, not the thread encrypted
- Consent stub and letter, to the fund granted
- Sent hardship fund, 2 documents delivered
- Employer no documents, no conversation private
- Outcome $312 paid to the electric company confirmed
- Documents stub and letter, task closed deleted
Complete. Nothing else was collected.
Why a secure page
Text is not encrypted end to end, and messaging apps keep copies. So CASEY never asks for a document or an ID detail in the thread. It sends a one-time link that expires in 24 hours.
Where the upload goes
Straight into Humanitas's audited systems, encrypted in transit and at rest. Sent on only after the person says yes, and deleted when the task closes.
Who sees what.
Aggregates are de-identified and released only above a cohort size set by re-identification risk. They never decide what anyone qualifies for or pays.
The person
Everything. Any detail CASEY holds about them, shown on request and corrected on request. They can leave at any time, and everything is deleted.
Their employer
Aggregate only. Risk by site, need by cohort, and what each intervention cost and returned. Never an individual's case, medical circumstance or household detail. Any connection to an employer's own systems is scoped to the workflow that needs it and nothing broader.
A public agency
Aggregate only. The funnel from reached to confirmed, where cases drop off, and which pathways work. Any detail about a single resident reaches the agency only through its own channel, when that resident submits it. CASEY never touches agency systems.
A provider
One request at a time. The need, the timing, the funding, and the requirements CASEY has already gathered, each with the person's authorization.
What CASEY learns about one person serves only that person. What it learns across many improves it for all.
The controls.
- Data
- Encrypted at rest and in transit. Labeled by sensitivity.
- Access
- MFA on critical services. Production access restricted and audit logged.
- Endpoints
- Anti-malware and encryption on every device, under mobile device management.
- Vulnerabilities
- Scanned and patched. Penetration tested, findings remediated.
- Infrastructure
- Web application firewall, infrastructure as code, changes reviewed. Backups automated and recovery plans tested.
- Incidents
- Incident response policy established. Infrastructure and network monitored.
- Vendors
- Inventoried and classified by data sensitivity and risk.
- People
- Security training, confidentiality agreements, onboarding and offboarding process.
Questions or a security report: [email protected]